
CVE-2026-50522: Microsoft SharePoint — Swiss Federal Accounts Compromised (July 2026)
CVE-2026-50522 — Microsoft SharePoint
CVE-2026-50522 is a high-severity vulnerability in Microsoft SharePoint, actively exploited in July 2026 to compromise user and technical accounts at Switzerland’s Federal Office for Information Technology and Communications (FOITT). The flaw enabled attackers to gain unauthorized access to approximately 200 accounts; no evidence of further data exfiltration has been reported as of this writing.
Attack Vector
Attackers targeted unpatched Microsoft SharePoint servers exposed to the internet, exploiting CVE-2026-50522 to bypass authentication and escalate privileges. The breach was detected on July 28, 2026, after anomalous account activity was observed. The attackers leveraged the vulnerability to compromise both user and technical accounts, indicating lateral movement capabilities. FOITT responded by blocking external internet access to SharePoint, resetting credentials, and reinstalling affected servers.
Who Is at Risk
All organizations running unpatched Microsoft SharePoint servers are at risk, especially those with internet-exposed deployments. The incident specifically impacted the Swiss Federal Office for Information Technology and Communications (FOITT), but the vulnerability is global in scope and could affect any SharePoint environment not yet remediated.
Patch & Mitigate
- Patch: Apply the latest Microsoft security update addressing CVE-2026-50522 immediately. Refer to Microsoft’s July 2026 security advisory for exact patch details.
- Workaround: Temporarily restrict external internet access to SharePoint servers if patching is delayed.
- Detect: Review authentication logs for unusual login attempts, privilege escalations, and access from unfamiliar IP addresses between July 20–31, 2026.
MITRE ATT&CK
- TA0001 — Initial Access: Attackers exploited SharePoint’s external exposure to gain a foothold.
- TA0005 — Defense Evasion: Use of privilege escalation and account compromise to evade detection.
- TA0006 — Credential Access: Compromise of user and technical accounts to facilitate further access.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

